Skip to main content

Minutes IETF122: scim: Wed 08:30
minutes-122-scim-202503190830-00

Meeting Minutes System for Cross-domain Identity Management (scim) WG
Date and time 2025-03-19 08:30
Title Minutes IETF122: scim: Wed 08:30
State Active
Other versions markdown
Last updated 2025-03-21

minutes-122-scim-202503190830-00

SCIM IETF 122

2025 03 19

(2569 BE)

Chairs Intro

welcome
note well
intro slides and how-tos
agenda review

Dean: any updates on Delta Queries?

Nancy: not adopted yet, ask on mailing list

SCIM Use Cases

Draft submitted to group last IETF
got some feedback, but lacking more.
This session will be an overview on what's in the draft.
Why is this needed? side conversations made it clear there needs to be
some common terms and concepts.

This will have generic and specialized use cases. Not exhaustive, but
sufficient.

Once the concepts from this document are agreed on, the drafts in
progress should be reviewed for consistency.

Terminology overview slide: data models, roles, actions, etc. This
terminology should be used in WG drafts.

Basic use cases slide: The goal is that these fit any of the flows
described today. resource subscriber, creator, and manager use cases.

Specific Use Cases slide: details of select use cases. Quick run through
of each one listed.
These are the use cases discussed in previous meetings.

Volunteers for review:

  • Dean
  • Anjali

Harvey wants the slides. They are available in the datatracker - meeting
materials.

SCIM Roles and Entitlements

Aaron presenting (chair hat off).

presenting on behalf of remote colleagues.

This was adopted and of 2022. Hasn't has much activity since, but is
being used.

Core schema defines roles and entitlements for users

This extension extends that, making the roles and entitelements managed
by the client.
Completes the half-picture drawn by the core vocabulary

Okta has implemented it and recommends some changes.

Summary of proposed changes slide: changes are currently sitting in a PR
on the repo

is adopted, but the original author has not pursued it. Folks at Okta
are looking to move it forward.

Has anyone reviewed this?

  • 🦗🦗

Nancy: make the updates, do a rev, then post to the mailing list.

Update from the OpenID IPSIE Working Group

Aaron is now wearing a slightly different hat (Open-ID). Still not a
chair one though.

Group is concerned with enterprise identity problems.

interop and security are two main themes of the work.

a lot of times there are enterprise identity providers who have utilized
the optionality available to them in the standards, which means every
implementation differs.

Lots of new threats as well. SSO was previously sufficient, but not
longer is enough. New threats require new solutions.

IPSIE Charter scope slide: some of the things are not as related to SCIM

goal is to profile existing specs as much as possible, to reduce the
optionality and pick the more secure ones. Allow users to follow specs
not vendor docs

What has this to do with SCIM?
Two lifecycles: session and identity, each with three levels
SCIM can likely ignore the session lifecycle
Identity lifecycles have overlap wuth SCIM WG drafts

Don't want to see IPSIE go off and profile SCIM on its own island. The
work should be done in conjuntion with this core SCIM group

IPSIE is trying to reuse as much of the existing infrastructure as
possble.

Feedback requested from SCIM implementers on the identity lifecycles
IPSIE has described, particularly as IPSIE profiles SCIM work.

IPSIE goals slide: they want stable drafts of first lifecycles by Sept
2025, demonstrate interop by Dec 2025. What does it actually look like
to use SCIM to achieve the goals of the first Identity Lifecycle

any comments or questions?

Dean: I co-chair this and would love to see folks in this room help. We
could use active deployers of SCIM to help us move forward. SCIM work
should be defined here, so that it can be used in IPSIE.

Nancy: one thing that would help us: can we have on the SCIM mailing
list a sharing of the documents. Is this public?

Aaron: it is public

Nancy: put it on the mailing list, hack on this at the next IETF
Hackathon, get live review in interim SCIM meeting.

Dean: would it be better for me to do this than Aaron?

Nancy: yes

Aaron: IPSIE is exclusively focused on enterprise use cases, SCIM is
not. This can serve to differentiate where the work happens. Want to
avoid OpenID defining the extensions.

Ali Hussein: what does enterprise cover?

Aaron: we have word-smithed our definition of enterprise

Dean: the way we defined enterprise is - if you consider yourself an
enterprise, you are. Government, small business, etc.

Aaron: if you want to control your overall application usage from a
single control point, you are an enterprise (i.e., in scope of IPSIE).

Dean: eduroam/internet 2 space are also involved.

Nancy: Please keep us up to date

Dean: we will

Justin: do we have a formal liasion relationship with OpenID and IETF?

Mike: No

Aaron: is that okay?

Nancy: it's pretty much the same people

Justin: our relationship with CNCF is also informal.

Nancy: deliberate, but informal

Mike Jones: There is a very long history of cooperation between OpenID
and IETF. OAuth, JOSE, etc. This works because people are inb both
places deliberately.

Nancy: I don't see the need for formality

AOB

Nancy: any other business?

No